PT-2026-99496 · WordPress · Online Scheduling/Appointment Booking System – Bookly
CVE-2026-86841
·
Published
2026-09-27
·
Updated
2026-09-28
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Online Scheduling and Appointment Booking System WordPress plugin versions prior to 28.3
Description
The plugin fails to prevent the deserialization of untrusted input and does not properly restrict a privileged maintenance feature to administrators. This allows users who have been explicitly assigned the
booking-management capability to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets. Deserialization is the process of converting a stored data format back into an object that the programming language can use.Recommendations
Update the Online Scheduling and Appointment Booking System WordPress plugin to version 28.3 or later.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Online Scheduling/Appointment Booking System – Bookly